Skip to content

Internal audit concepts

Internal audit provides independent, objective assurance and consulting designed to add value and improve an organisation’s operations. Nextera Trace is built around this professional cycle rather than around a generic task tracker, so this page covers that cycle.

Independence is a constraint on the system, not just on the people

Section titled “Independence is a constraint on the system, not just on the people”

The defining characteristic of internal audit is that it is independent of the activities it audits. Independence is organisational — internal audit reports functionally to the audit committee and administratively to management — and objectivity is the individual equivalent: no auditor assesses work they performed or advised on.

This has direct consequences for how an audit system must behave, which is why it belongs on a concepts page rather than in a policy document:

  • Management can be given read access to results, but must not be able to alter a finding, its rating, or its evidence.
  • The person who agrees a management action and the person who verifies it was completed cannot be the same person.
  • The audit trail on ratings and conclusions matters more than in most systems, because the value of a finding is partly its unamended provenance.

The audit charter is the board-approved document establishing internal audit’s purpose, authority, reporting lines and right of access. Everything else derives from it. Internal audit’s professional framework comes from the Institute of Internal Auditors.

Nextera Trace translates this very directly: every Trace account belongs to the audit function itself. Users are created per organisation with one of five roles — Partner, Manager, Supervisor, Senior, Junior — and there is no auditee login. The preparer/reviewer separation is enforced as a status rather than as a verbal understanding: once a working paper reaches Submitted its form locks read-only, and every status change is recorded in that paper’s History panel together with who moved it, when, and what they noted. The team’s declaration of independence is itself recorded as a separate working paper, from the A150 Pernyataan Independensi template.

The audit universe is the complete population of things that could be audited — entities, business units, processes, systems, geographies, third parties, and risk themes.

Two properties make it useful rather than decorative:

  • It is maintained, not rebuilt. A universe reconstructed each year loses the history of what was audited when, which is the input the plan most needs.
  • Its granularity is consistent. A universe mixing “the Surabaya branch” with “the entire finance function” cannot be prioritised sensibly, because the units are not comparable.

Each auditable unit carries risk attributes, an owner, and — crucially — when it was last audited and what was found.

Coverage is the question the universe exists to answer: what proportion of the universe, weighted by risk, has been audited within the cycle? An area never audited in five years is a finding about the plan, not about the area.

One thing to know up front, so you do not go hunting for it in the menu: Nextera Trace has no audit universe module. Trace manages engagements one at a time. The mapping section at the end of this page sets out what the product holds and what you still maintain outside it.

The annual plan is built from the universe, prioritised by risk. A defensible plan usually weighs:

  • Inherent risk of the auditable unit — materiality, complexity, change, regulatory exposure, fraud susceptibility.
  • Control maturity, where known — often informed by the organisation’s ICoFR work in a system like Nextera Guard.
  • Time since last audit, and what that audit found.
  • Management and audit committee requests, held in tension with independence: internal audit takes input on the plan, but the plan is not set by the auditee.
  • Available resource — the plan is constrained by auditor days, and pretending otherwise produces a plan that fails in Q3.

Assurance mapping is the discipline of recording who else already provides assurance over each area — external audit, regulators, second-line functions, certification bodies — so internal audit can direct effort where it is the only assurance, rather than duplicating.

Plans change. What matters is that changes are visible and approved, not that the plan was perfect in January.

An engagement runs through a recognisable sequence:

  1. Scope and terms of reference. Objectives, boundaries, period, criteria, and the engagement’s own risk assessment. Agreed with the auditee, approved within audit.
  2. Planning. The audit programme — what will be tested, how, and by whom.
  3. Fieldwork. Performing the tests and gathering evidence.
  4. Working papers. The record of what was done.
  5. Findings. Raised, discussed, and agreed with management.
  6. Report. Issued to management and, in summary, to the audit committee.
  7. Follow-up. Verification that agreed actions were completed.

Working papers carry a specific professional standard: a competent reviewer with no prior connection to the engagement should be able to read them and understand what was tested, what was found, and why the conclusion follows. That standard — not tidiness — is what makes working paper structure worth enforcing.

Review is the corresponding control: work is reviewed by someone more senior before conclusions are issued, and the review itself is evidenced.

That sequence takes the shape of a single Engagement record holding a set of Working Papers. Each working paper is generated from a Template, and on the Working Papers tab of the Engagement page they are grouped into the categories A1 Pre-Engagement, A2 Planning, B Execution and C Completion.

The built-in template library is numbered by series:

Series What it holds Examples
A110–A170 Engagement acceptance, set-up, time budget A150 Pernyataan Independensi, A120 Alokasi Jam Jasa dan Perencanaan Lainnya
B100–B280 Procedures and testing B210 Pengujian Pengendalian, B230 Pengujian Substantif - Piutang
C100–C400 Completion, conclusions, reporting C110 Evaluasi Salah Saji, C300 Ringkasan Audit

Every template carries Standard references to the Indonesian auditing standards, Standar Audit (SA) — A150 to SA 200, B210 to SA 330 and SA 500, C110 to SA 450, and so on — so the professional basis for each working paper can be read straight off its screen.

The review runs as a fixed status flow:

Not Started → Draft → In Progress → Submitted → In Review → Completed, with a single Rework path back when a reviewer returns the paper.

  • The preparer writes the paper and presses Submit.
  • Only the Partner, Manager or Senior roles can take a Submitted paper into In Review.
  • Only the reviewer assigned to that paper can approve it to Completed or return it to Rework — and a return must carry a reason.
  • Completed is a final status. There is no transition out of it.

This is the concrete form of the working paper standard above: evidence of review does not have to be hunted down, because it is the paper’s own status history.

Every well-formed finding has all five. Missing elements are the most common reason a finding is disputed or ignored:

Element The question it answers
Criteria What should be happening — policy, standard, regulation, control design
Condition What is happening
Cause Why the gap exists
Effect What the gap could lead to — quantified wherever possible
Recommendation What should change

Cause is the element most often skipped, and it is the one that determines whether remediation works. A finding that says “reconciliations were not performed” without establishing why — no owner, no time, no system access, no understanding of the requirement — produces a management action that fixes the symptom and recurs next year.

Effect is what converts a finding from an observation into a priority. “Three of twenty reconciliations were late” is an observation; “three of twenty reconciliations were late, covering IDR 40 billion of balances, and one contained an uncorrected error” is a finding.

Ratings exist so that limited management attention goes to the right places. Any scale works as long as it is defined, applied consistently, and calibrated against impact and likelihood rather than against how annoyed the auditor was.

Two rating levels are usually needed and often confused:

  • Finding rating — the severity of the individual issue.
  • Engagement opinion — the overall conclusion on the area audited. An area can receive several low findings and still warrant an adverse overall opinion if together they show the control environment is weak.

Definitions should be published in the methodology and applied by the same people who wrote them. An unwritten scale becomes a negotiation.

In Nextera Trace the two levels are not two configurable scales. There is no separate finding record to rate; the engagement-level conclusion is recorded on the C300 Ringkasan Audit working paper in the Jenis Opini field, with four built-in options — Tanpa Modifikasi (WTP), Wajar Dengan Pengecualian (WDP), Tidak Wajar (TW), and Tidak Menyatakan Pendapat (TMP). Where those options do not match your methodology, the thing you change is the template: through Templates → Edit template an organisation can add and adjust sections and fields, and the result is saved as a version of your own — the built-in template is left untouched.

Each finding gets a management response containing three things and no fewer: an agreed action, a named owner, and a due date. “Noted” is not a response.

Where management accepts the risk rather than acting, that is a legitimate outcome — but it must be explicitly recorded as risk acceptance at an appropriate level of authority, not allowed to become a permanently overdue action.

Follow-up is where most audit functions lose value, and the reason is structural rather than cultural. Findings are raised in engagement-shaped batches, but they come due continuously and long after the engagement closed. If actions live in the engagement’s own file, nobody can answer the audit committee’s actual question — how many high-rated actions are overdue across everything? — without reassembling it by hand.

Verification closes the loop: internal audit confirms the action was completed and, more importantly, that it addressed the cause. Closing on management’s assertion alone undermines the whole cycle.

What this looks like in Nextera Trace is worth knowing plainly. Management responses are recorded by the auditor as fields inside a working paper — Tanggapan Manajemen and Alasan Tidak Dikoreksi on C110 Evaluasi Salah Saji, and the matters that must be communicated together with their responses on C230 Komunikasi dengan TCWG. Because there is no auditee login and no action register spanning engagements, tracking to closure and recording risk acceptance remain your own function’s process, outside the product.

Audit committee reporting is a different product from an engagement report, drawn from the same data: plan progress against the approved plan, coverage of the universe, findings by rating and by theme, overdue actions with ageing, and matters the committee needs to decide.

The value of generating it from the same underlying records is that the numbers cannot drift between the engagement file and the committee pack — which is the failure mode of every spreadsheet-based audit function.

Trace does not use “audit universe” or “follow-up tracking” as module names. What you meet in the sidebar is eight main menus — Dashboard, Engagements, My Tasks, Templates, Analytics, Reports, Team, Activity — plus Integrations, Settings and Help at the bottom. All of them turn around a single primary record: the Engagement.

Concept on this page Where it lives in Nextera Trace
One audit engagement, from set-up to conclusion The Engagement record, in the Engagements menu
Engagement acceptance, independence, time budget A series working papers — A110 to A170
Fieldwork and testing B series working papers — B100 to B280
A record of the work that a reviewer can read Working Papers inside the Engagement, built from Templates
Review by someone more senior, and its evidence The Submitted → In Review → Completed or Rework statuses, plus the History panel
Findings and control deficiencies Fields inside the working papers — B100 Ringkasan Temuan, C300 Temuan Utama, C230 Defisiensi Pengendalian Internal
The overall conclusion on the area audited C300 Ringkasan Audit, the Jenis Opini field
Communication with those charged with governance C230 Komunikasi dengan TCWG
Reporting that can be shared outside the system Reports & Exports — PDF, Word or Excel, per paper or as one engagement bundle
Progress, team workload, completion trends Analytics
The trail of who changed what Activity for the organisation, History for each working paper